Back to skill

Security audit

钦天监

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it gives directive crypto and investment-timing guidance from speculative cycle claims without clear risk limits or financial-advice disclaimers.

Review this skill carefully before installing if you might act on crypto or investment advice. Treat its cycle scores, BTC sentiment mapping, and multi-year forecasts as speculative commentary only, not personalized financial advice or a basis for trading decisions. The external BTC sentiment fetch is disclosed and appears narrow, but the skill should not send private user context to that API.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section gives concrete portfolio/trading recommendations such as lowering exposure to high-risk assets and focusing on specific sectors, without suitability checks, risk disclosures, or uncertainty framing. Because the skill is explicitly tied to crypto and investment timing, this can directly influence user asset allocation and losses.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The QCX section operationalizes a scoring model into action-oriented trading behavior like 'cash is king,' 'wait to buy the dip,' and 'actively participate,' while presenting computed outputs as actionable signals. Users could treat the score as authoritative despite the model being speculative and lacking validation, making financial harm likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides multi-year forecasts, warning years, and allocation suggestions as if they are dependable planning inputs, without disclosing that these are speculative predictions. Long-range financial forecasts can strongly influence user behavior, especially when paired with phrases like 'cash is king' or 'actively position,' increasing the chance of material losses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README presents the skill name, description, features, and usage instructions only in Chinese, and does not provide an opt-in or alternative language. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill positions itself around cycle-based economic prediction and investment decision support, but does not clearly warn users that the content is speculative, non-financial-advice, and may be inaccurate. In a trading/crypto context, users may rely on these claims to make real financial decisions, creating foreseeable harm from unsupported predictive guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill instructs the agent to call an external API to retrieve BTC sentiment data, which creates an outbound data flow and dependency on third-party content. While the referenced API itself is not obviously malicious here, external transmission can expose user context or enable untrusted data to shape financial outputs if requests are not tightly controlled.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

当用户发送 /qcx 时,自动获取当前 BTC 情绪指数:

text
调用 API:https://api.alternative.me/fng/

当前实时数据:

Static analysis

No suspicious patterns detected.